File name:

3k7RNwxPVP2bvx7kUmCHwf.zip

Full analysis: https://app.any.run/tasks/7558dcb0-ec95-40b5-a3a9-d051b084db59
Verdict: Malicious activity
Analysis date: February 29, 2024, 04:27:32
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

E9ADBC31445CB22DFA5A22E8ABB3328E

SHA1:

CED99FD82FA76031426AE079270091438F1F1293

SHA256:

B6626E55F517B2BB9C095E7BB34C1C2FC35C34D31E2CAA07B48EE9F61E6E97FF

SSDEEP:

393216:Wh49tDS1kULF9KsXQKYFZ9HFc79xWMIQBg6nSnu4sCmM7galnsl6GT3wBo:WefDS1LL7SZ9lcBMMxguSu4t5hENqo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • PdfConverters.exe (PID: 5608)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • PdfConverters.exe (PID: 5608)
    • The process creates files with name similar to system file names

      • PdfConverters.exe (PID: 5608)
    • Executable content was dropped or overwritten

      • PdfConverters.exe (PID: 5608)
    • The process drops C-runtime libraries

      • PdfConverters.exe (PID: 5608)
  • INFO

    • Reads the software policy settings

      • slui.exe (PID: 3240)
    • Checks proxy server information

      • slui.exe (PID: 3240)
    • Checks supported languages

      • PdfConverters.exe (PID: 5608)
    • Reads the computer name

      • PdfConverters.exe (PID: 5608)
    • Manual execution by a user

      • PdfConverters.exe (PID: 5608)
      • firefox.exe (PID: 4008)
    • Create files in a temporary directory

      • PdfConverters.exe (PID: 5608)
    • Reads Microsoft Office registry keys

      • firefox.exe (PID: 6040)
    • Creates files in the program directory

      • PdfConverters.exe (PID: 5608)
    • Application launched itself

      • firefox.exe (PID: 4008)
      • firefox.exe (PID: 6040)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0009
ZipCompression: Deflated
ZipModifyDate: 2024:02:29 04:02:18
ZipCRC: 0x0188e77a
ZipCompressedSize: 63572532
ZipUncompressedSize: 157801528
ZipFileName: PdfConverters.exe_
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
15
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs slui.exe pdfconverters.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1108"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="6040.1.2021876536\1663587235" -parentBuildID 20230321111920 -prefsHandle 2296 -prefMapHandle 2292 -prefsLen 27131 -prefMapSize 238085 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {c9e56d24-fc34-484e-b770-2671055ec0b3} 6040 "\\.\pipe\gecko-crash-server-pipe.6040" 2308 22838bfaf58 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
111.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
1776"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="6040.0.1238108991\920167161" -parentBuildID 20230321111920 -prefsHandle 1740 -prefMapHandle 1732 -prefsLen 27131 -prefMapSize 238085 -appDir "C:\Program Files\Mozilla Firefox\browser" - {4ef95b98-cec4-4b70-b367-4d56d1565c45} 6040 "\\.\pipe\gecko-crash-server-pipe.6040" 1820 228380a9358 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
1
Version:
111.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2152"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="6040.3.330861290\118842026" -childID 2 -isForBrowser -prefsHandle 4268 -prefMapHandle 4264 -prefsLen 32967 -prefMapSize 238085 -jsInitHandle 1504 -jsInitLen 246560 -a11yResourceId 64 -parentBuildID 20230321111920 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {8a5beae0-0602-43d2-83a4-ea3723ca5634} 6040 "\\.\pipe\gecko-crash-server-pipe.6040" 4280 2282b97c258 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
111.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3240C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
3652"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="6040.7.1646264698\1149318849" -childID 5 -isForBrowser -prefsHandle 5108 -prefMapHandle 5140 -prefsLen 29575 -prefMapSize 238085 -jsInitHandle 1504 -jsInitLen 246560 -a11yResourceId 64 -parentBuildID 20230321111920 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {5ad1a697-36a2-4f16-ab71-9420bb263fb1} 6040 "\\.\pipe\gecko-crash-server-pipe.6040" 5348 2282b976d58 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
111.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3824"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="6040.4.554539745\1284006986" -parentBuildID 20230321111920 -sandboxingKind 0 -prefsHandle 5020 -prefMapHandle 4956 -prefsLen 32967 -prefMapSize 238085 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {15cf5dd2-506a-4a00-8798-21526ac3cc6b} 6040 "\\.\pipe\gecko-crash-server-pipe.6040" 2484 228419a0258 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
1
Version:
111.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3872"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="6040.5.2112259970\1319163800" -childID 3 -isForBrowser -prefsHandle 2484 -prefMapHandle 4300 -prefsLen 29575 -prefMapSize 238085 -jsInitHandle 1504 -jsInitLen 246560 -a11yResourceId 64 -parentBuildID 20230321111920 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {ad3e2ef5-0c8d-4251-b366-3d894d903a7f} 6040 "\\.\pipe\gecko-crash-server-pipe.6040" 5108 228414ce858 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
111.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3980"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="6040.9.1837401434\1898539304" -childID 7 -isForBrowser -prefsHandle 4676 -prefMapHandle 8228 -prefsLen 29760 -prefMapSize 238085 -jsInitHandle 1504 -jsInitLen 246560 -a11yResourceId 64 -parentBuildID 20230321111920 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {3970a3d3-dfd8-4872-8acf-cd1810e02bda} 6040 "\\.\pipe\gecko-crash-server-pipe.6040" 5996 2282b97a458 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
111.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4008"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
111.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\bcrypt.dll
4744"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="6040.8.1602832527\524823201" -childID 6 -isForBrowser -prefsHandle 9836 -prefMapHandle 9844 -prefsLen 29760 -prefMapSize 238085 -jsInitHandle 1504 -jsInitLen 246560 -a11yResourceId 64 -parentBuildID 20230321111920 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a8b4e1d8-6c02-45b9-ae8d-38d5ca753875} 6040 "\\.\pipe\gecko-crash-server-pipe.6040" 9848 2282b9f6358 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
111.0.1
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
Total events
22 829
Read events
22 696
Write events
128
Delete events
5

Modification events

(PID) Process:(5192) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\General
Operation:writeName:VerInfo
Value:
005B0500B0C0A4AFC76ADA01
(PID) Process:(5192) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(5192) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(5192) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\3k7RNwxPVP2bvx7kUmCHwf.zip
(PID) Process:(5192) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(5192) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(5192) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(5192) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(5192) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\36\52C64B7E
Operation:writeName:@C:\WINDOWS\System32\msxml3r.dll,-1
Value:
XML Document
(PID) Process:(5192) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:writeName:0
Value:
C:\Users\admin\Desktop
Executable files
521
Suspicious files
102
Text files
31
Unknown types
55

Dropped files

PID
Process
Filename
Type
5192WinRAR.exeC:\Users\admin\Desktop\PdfConverters.exe_
MD5:
SHA256:
5192WinRAR.exeC:\Users\admin\Desktop\files-raw.3uPldrSbfKe9uMLx0HW61a.xmlxml
MD5:A604F740DE8E95CB45BE4D4506D70B20
SHA256:1642F226204E9BAEFACDD400822AF65E60D5C7ED8A47DFC2B0318486F3B7575E
5192WinRAR.exeC:\Users\admin\Desktop\sysinfo.c2Ai88Ejg6aiIRz56Whd6g.xmlxml
MD5:7C1A0BC45E6219B05893A51EF9BBB6CF
SHA256:BA367CE9CA6382B89A5F29B96CD38BCE67E535F9C33BE30EC100060A5D14396A
5192WinRAR.exeC:\Users\admin\Desktop\metadata.jsonbinary
MD5:95FCE83AD576041CC8736DA4861E0C78
SHA256:ADD0E14D139592CB68E52EF81EB27699C0AE612C3F24F7297BA7CCC92E17E761
5192WinRAR.exeC:\Users\admin\AppData\Roaming\WinRAR\version.datbinary
MD5:5C4722E77AF091CF0227BAA139F59763
SHA256:FF9E7E75FCAB0E495F80BD49BDB121B5DDC63A44F0E52C8771A70407A0EA8E70
5192WinRAR.exeC:\Users\admin\Desktop\manifest.jsonbinary
MD5:18A68CA6E45E50B66A02C2BBAAA0FB04
SHA256:D2D4C03C6B4D072B0DAF6BB5E8AB74D117E314B3DACEE7067E0BAAB1E5114207
5608PdfConverters.exeC:\Users\admin\AppData\Local\Temp\.net\PdfConverters\15e8\Microsoft.VisualBasic.Core.dllexecutable
MD5:4CA0C139B698FF4B1A4FBAF653D8B607
SHA256:E0864F46E0F0CA66143B43C12A4B37DBE2FBE8FD138D5DA59326FD632D6A3571
5192WinRAR.exeC:\Users\admin\Desktop\script.xmlxml
MD5:05EC1354343915BDBABBDD854C5EE103
SHA256:BB495FE88A706E18C531E53C52D2F8CFFF4840387BC3F75C1E8E2747773E7951
5608PdfConverters.exeC:\Users\admin\AppData\Local\Temp\.net\PdfConverters\15e8\Microsoft.Win32.Registry.dllexecutable
MD5:F8B9909E9BBCBEEA830CC601BC66963F
SHA256:7B38E022604BFC8820C476926D21DA8079EA59263A5B90AF3221D8232F2E9ED3
5608PdfConverters.exeC:\Users\admin\AppData\Local\Temp\.net\PdfConverters\15e8\Microsoft.CSharp.dllexecutable
MD5:EF890172F46CC8AEB5E9A73F94285FBA
SHA256:C7A8497165273BDA4CB92EDB6758E3FB1DEB78F9670FB1471A79550CA5D8D065
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
26
TCP/UDP connections
90
DNS requests
132
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
6040
firefox.exe
POST
200
23.32.238.49:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
1296
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
unknown
binary
471 b
unknown
6188
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
313 b
unknown
2720
svchost.exe
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
binary
1.01 Kb
unknown
2464
svchost.exe
GET
200
2.23.197.184:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
6040
firefox.exe
POST
200
23.32.238.49:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
6040
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
text
90 b
unknown
6040
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
unknown
6040
firefox.exe
POST
200
23.32.238.49:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
3848
svchost.exe
239.255.255.250:1900
unknown
6896
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5928
svchost.exe
20.190.159.73:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5928
svchost.exe
20.190.159.4:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5928
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2720
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6828
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2720
svchost.exe
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
ocsp.digicert.com
  • 192.229.221.95
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.49
whitelisted
www.bing.com
  • 2.19.96.128
  • 2.19.96.66
  • 2.19.96.107
  • 2.19.96.80
  • 2.19.96.83
  • 2.19.96.120
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 20.114.59.183
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.166.126.56
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
x1.c.lencr.org
  • 2.23.197.184
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.43
whitelisted

Threats

No threats detected
Process
Message
PdfConverters.exe
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.